Anonymized post-mortems still traceable by timestamp and prefix size tho
True but you can fuzz timestamps to the week and collapse prefixes to the RIR allocation size, the educational value is in the topology and the filtering failure, not the exact victim Contabo actually did something like this internally after their 2021 leak, I heard secondhand it became required reading for new NOC hires and their repeat incident rate dropped hard The jurisdiction question is the real blocker, even a GitHub org can be subpoenaed Maybe the answer is a dead-drop model: operator submits to a neutral third party who scrubs and publishes with a 90-day lag, no logs retained Has anyone actually asked their legal team whether "we caused a leak and here is how our prefix filters failed" is more dangerous than staying silent? I suspect the risk is overstated once names are removed
Post a reply
You need an account to reply.
Log in or
register to join the conversation.